← All documents

Security

Technical overview for security reviews. Version: August 2026. Operator: Artur Parutkin (sole proprietorship), Isestraße 35, 20144 Hamburg, Germany.

This page describes technical operations. The binding commitments are the DPA and the TOM (Annex 2, Art. 32 GDPR); where they differ, the contracts govern.

Section 10 lists what we do not claim.


1. Where your data is processed

What Where Provider
Application, database, backups Falkenstein, Germany Hetzner
AI inference (prompts & outputs) France, EU Scaleway
Transactional email (magic link, confirmations) USA — EU Standard Contractual Clauses Resend
Payment processing USA — EU Standard Contractual Clauses Stripe

Your prompts and documents stay in the EU, processed exclusively by European providers. US processors touch only ancillary data (email address for login delivery, payment data) under SCCs — not your content.

Dedicated AI hosting in Germany: Enterprise option on request.


2. What we store — and what we don't

Not stored

Basis: Scaleway AI Conditions Art. 4.4. For the one exception, see section 10.

Stored

Retention

Web server access logs 14 days. Application and container logs rotate, 30 days maximum. Analytics and security telemetry (page views, bot visits, honeypot triggers) 90 days, enforced by a nightly purge — IP addresses there exist only as a salted hash. Account data until erasure on request (Art. 17 GDPR).


3. Encryption


4. Access and authentication


5. Backups and recovery


6. Monitoring and incident response

Real-time alerts on: admin-panel login · changes to users, privileges, SSH keys, cron jobs, or listening ports · failed backups.

Logs are retained off the server and therefore cannot be altered or deleted from the affected system in the event of a compromise.

Documented procedure: detection, assessment of severity and affected data, containment (blocking access and keys, isolation), notification, documentation.


7. Sub-processors

Complete, current list: Sub-processors. All are bound by a DPA under Art. 28 GDPR; EU Standard Contractual Clauses apply for non-EU providers.

We announce changes 30 days in advance (§ 5 DPA), so you can object.


8. Compliance status

Status
GDPR DPA available, publicly readable, Art. 28 structure
EU AI Act Provider of a general-purpose AI system. Not high-risk, no Art. 5 practices. Art. 50 transparency obligations met. We do not train our own models.
§ 203 StGB Confidentiality undertaking available
ISO 27001 / SOC 2 (our own) ❌ None
External penetration test ❌ Planned, not yet performed

Certifications held by our sub-processors (not by us): Hetzner ISO 27001, Scaleway ISO 27001, Resend SOC 2 Type II with a pen-test attestation.

Does your procurement require a certification of our own? Ask — we will give you the status and timeline.


9. Reporting a vulnerability

security@privatai.com · machine-readable: /.well-known/security.txt

No social engineering, physical security testing, load testing / DoS, or access to other people's data.


10. What we do not claim


Security review or technical questionnaire? Get in touch.